CVE-2026-70615 HIGH

CVE-2026-70615: boringproxy 0.10.0 SSH authorized_keys Injection via Tunnel Creation

Vendor Boringproxy
Product boringproxy
Weakness CWE-93 · CRLF injection
Published August 5, 2026
Last update August 6, 2026

CVSS base score

8.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H

What the vulnerability does

01Description

boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in the domain parameter of the tunnel creation endpoint. Attackers can insert an unrestricted public key entry into authorized_keys to gain persistent shell access, and subsequently read cleartext credentials from the database file including all user tokens, tunnel private keys, and TLS certificates.

Key dates

02Disclosure timeline

August 5, 2026 CVE published
August 6, 2026 Record updated

Related vulnerabilities

04Related CVE